• Information Security Engineer

    Job Locations
    US-CA-San Francisco
    Information Security
  • Overview

    First Republic is an ultra-high-touch bank that provides extraordinary client service. We believe that one-on-one interactions build lasting relationships. We move quickly to serve our clients’ needs so that their financial transactions are handled with ease and efficiency. Client trust and security are paramount in our line of business. Ultimately, our goal is unsurpassed client satisfaction which will lead to personal referrals – our number one source of new business. We recognize that our competitive advantage starts with our people and our culture. At First Republic, we work hard and move quickly as a very coordinated team. If you are looking for an opportunity to grow and contribute in a fun, fast-paced environment, First Republic is the place for you. We have exceptional people focused on providing extraordinary service.


    The Information Security Engineer provides security oversight to First Republic Bank’s computing environment. 


    Oversight is achieved by monitoring and investigating security events as reported by FRB’s SIEM; developing SIEM correlation rules to meet regulatory compliance requirements; identifying and addressing potential data loss channels; and staying apprised of potential security challenges through the gathering and processing of cyber intelligence.


    • Security Information and Event Management: Configuration of Information Security monitoring systems which provide logging, monitoring, and actionable alerting. Systems include IDS/IPS; Database Activity Monitoring; and Vulnerability Scanners. Assist with the configuration, maintenance, and monitoring of the Security Incident and Event Monitoring (SIEM) system.
    • Develop and implement SIEM use cases to support the monitoring of the Bank’s infrastructure and ensuring that regulatory and legal compliance (e.g. GLBA, SOX) is maintained and compliance with Bank policy is maintained. Support the incident response team, by providing tier 2 support to incident handlers.         
    • Data Loss Prevention Program: Support the enterprise data loss prevention program by identifying and controlling data loss channels. As directed, work with business units to address their data loss prevention requirements.
    • Cyber Intelligence Analysis: Monitor cyber intelligence and provide input as necessary to other groups within the Bank. Take proactive steps, such as implementing controls, to reduce the likelihood of a successful attack. Update incident response procedures as necessary based upon cyber intelligence.
    • Project Consulting: Provide security consulting services, as needed, to various projects. Provide assistance to the Information Security Architect in the design of security solutions.


    • BS in Computer Science or equivalent.
    • Technical network (e.g. CCNA, CCNP Security) and security certifications highly desirable (e.g. CISA, CISSP, GCIH).
    • Understanding of controls (e.g. access control, auditing, authentication, encryption, integrity, physical security, and application security).
    • Must be well versed in Windows environments, Active Directory, VPN systems, encryption schemas and algorithms, various authorization and authentication mechanisms/software, network monitoring and sniffing, TCP/IP networks and vulnerability and threat management tools (including network based scanners).
    • Beneficial if experienced in Database Activity Monitoring Systems (DAM), and Web Application Firewalls (WAF).
    • Ability to provide quality deliverables on time and on budget.


    Mental/Physical Requirements:

    • The ability to learn and comprehend basic instructions; understand the meanings of words and respond effectively; and perform basic arithmetic accurately and quickly.
    • Vision must be sufficient to read data reports, manuals and computer screens.
    • Hearing must be sufficient to understand a conversation at a normal volume, including telephone calls and in person.
    • Speech must be coherent to clearly convey or exchange information, including the giving and receiving of assignments and/or directions.
    • Position involves sitting most of the time, but may involve walking or standing for brief periods of time.
    • Must be able to travel in a limited capacity.


    Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
    Share on your newsfeed